CRITICAL🇵🇱 Wersja polska

CVE-2016-6646

CVSS 9.8v3.0pub. 2016-10-05upd. 2026-05-06

The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2) RemoteServiceHandler class.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dell Emc Unisphere

    APP
    Dell
    8.08.18.1.28.2
  • Emc Solutions Enabler

    APP
    Emc
    8.08.0.38.18.1.28.3
  • Emc Unisphere

    APP
    Emc
    8.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2018-1183CRITICAL9.8PL ✓same product

XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)

CVE-2017-14375CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia w EMC Unisphere, Solutions Enabler, VASA i VMAX eManagement

CVE-2016-0889CRITICAL9.8PL ✓same product

Zapis do dowolnych plików w EMC Unisphere for VMAX Virtual Appliance

CVE-2016-6645HIGH8.8same product

The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions E...

CVE-2015-0545HIGH10.0same product

EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allow...